kubernetes-sigs / kueue

Kubernetes-native Job Queueing
https://kueue.sigs.k8s.io
Apache License 2.0
1.26k stars 223 forks source link

Add in-scope/out-scope subsections to SECURITY-INSIGHTS.yml #1473

Open psschwei opened 6 months ago

psschwei commented 6 months ago

#SecuritySlam

What would you like to be cleaned:

When the SECURITY-INSIGHTS.yml file was initially created in https://github.com/kubernetes-sigs/kueue/pull/1469, the in-scope / out-scope subsections of the vulnerability-reporting section were omitted, as it was not entirely clear which of the OWASP Top 10 were in/out of scope. Someone with more knowledge of the project should update the SECURITY-INSIGHTS.yml file to include this section.

Why is this needed:

Adding this section will improve the project's score on the CLOMonitor site.

/sig release

k8s-triage-robot commented 3 months ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

tenzen-y commented 3 months ago

/remove-lifecycle stale

k8s-triage-robot commented 3 weeks ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

tenzen-y commented 3 weeks ago

/remove-lifecycle stale